Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Overview
A new botnet called Tengu, derived from the well-known Mirai botnet, has been identified targeting compromised Linux devices. Researchers from Nozomi Networks Labs found that Tengu can utilize a device's hardware watchdog feature to reboot itself whenever defenders attempt to terminate its main process. This persistence method allows Tengu to re-establish its operation even after being interrupted. The botnet primarily gains access through brute-force attacks on Telnet credentials. Tengu is capable of launching distributed denial-of-service (DDoS) attacks, which can overwhelm targeted systems and disrupt online services. This incident raises concerns for organizations relying on Linux devices, as Tengu's ability to persist poses a significant challenge for cybersecurity defenses.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Compromised Linux devices, specifically those using Telnet for remote access.
- Action Required: Users should disable Telnet access, implement strong password policies, and consider monitoring for unusual device behavior to mitigate risks associated with Tengu.
- Timeline: Newly disclosed
Original Article Summary
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (
Impact
Compromised Linux devices, specifically those using Telnet for remote access.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should disable Telnet access, implement strong password policies, and consider monitoring for unusual device behavior to mitigate risks associated with Tengu.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, Botnet, DDoS.